Third-party Windows MDM: How do we get the Entra Device ID in the v2 access token sent during MDM enrollment?

Victor Lyuboslavsky 0 Reputation points
2026-10-05T15:13:15.4866667+00:00

We are implementing a third-party MDM that uses the Windows MDM enrollment protocol and integrates with Microsoft Entra. During automatic MDM enrollment, Windows sends an Entra access token to our enrollment endpoint. With a v1 token we can obtain the device ID claim, but with the v2 token we are receiving, the device ID is absent. Is there a supported way for a third-party MDM application to configure/request the v2 token so that it contains the Entra device ID (deviceid claim)? If not, what is the supported mechanism for associating the enrollment request with the Entra device object?

Adding deviceid as an optional claim appears to work, even though it shows a yellow warning sign.
User's image

Microsoft Security | Microsoft Entra | Other
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.